SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Cameras evolve as physical security becomes part of IT stack

Cameras evolve as physical security becomes part of IT stack

Wed, 9th Sep 2026 (Today)
David Shilovsky
DAVID SHILOVSKY Interview Editor

Physical security systems are increasingly being integrated into corporate IT environments as organisations look to extract more value from cameras and other security devices beyond their traditional use cases.

Physical security and IT operations within companies have become considerably more intertwined over the past decade.

Speaking at Security Exhibition 2026 in Sydney, Sales Engineering and Training Manager at Axis Communications, Oshana Jouna, said cameras are now being treated as networked computing devices capable of generating data and supporting broader business operations, 

"When I started at Axis in 2015, the security industry was separate," Jouna said.

"Now we are seeing it getting closer and closer together."

While security remains the primary purpose of cameras and access-control devices, the analytical capabilities built into modern security systems are creating opportunities across other areas of a business, including operations, marketing and sales.

Axis customers operating in the retail industry use camera-generated data to understand how many people are entering a store and where customers are concentrating, potentially allowing it to optimise store layouts or develop more targeted marketing strategies.

That convergence between physical security and IT, however, is also creating new cybersecurity challenges as organisations connect increasing numbers of IoT devices to their corporate networks.

One of the key concerns facing IT teams is the expansion of the attack surface created by bringing cameras and other connected devices into existing infrastructure.

The solution is not to keep physical security systems isolated from IT networks, Jouna explained, but to ensure the devices being introduced are designed with cybersecurity requirements in mind.

For Axis, that means incorporating security throughout the product lifecycle, rather than treating cybersecurity as a feature that can simply be switched on.

"Cybersecurity is not a button that you press and it's enabled," Jouna said.

"It's all the hardware that you put in the product, the firmware that sits on top of that, all the device IDs and encrypted certificates, and the way you store them inside the camera."

Axis also focuses on how those devices can be securely deployed and managed at scale, which is becoming more important as organisations operate security systems across multiple sites.

Jouna cited a large customer deployment, involving approximately 3000 cameras spread across multiple sites throughout New Zealand.

Each site has around 100 cameras, creating a significant management challenge for the customer.

Instead of requiring technicians to travel between locations to perform routine tasks, organisations need the ability to centrally monitor, update and configure their devices.

Physical maintenance will still be required, but many administrative and cybersecurity tasks can now be handled remotely.

That includes ensuring cameras are running the latest firmware, managing passwords and certificates, identifying devices that have gone offline and applying configuration changes across multiple devices.

Cloud services play a major role in making this possible, particularly for organisations with operations spanning vast geographical areas.

Axis uses its Axis Cloud Connect platform to provide cloud-based capabilities for managing devices and connecting technology partners, with the company seeking to maintain an open ecosystem rather than locking customers into a single set of applications.

The approach is particularly important as organisations move more security workloads into cloud environments.

However, Jouna warned that connecting a camera directly to the internet inherently introduces considerable security risks if the device is not adequately protected.

"As soon as you put a camera on the internet, it's hackable," he said.

Axis therefore builds security into its products from the design stage, including the use of hardware-based security technology, trusted execution environments and secure device identities.

They ship cameras with security enabled by default, using tech designed to ensure firmware has not been compromised.

Another capability is signed video, designed to help establish that footage originated from a particular camera and has not been tampered with.

These capabilities are becoming increasingly important as video moves beyond its traditional role as evidence that can be reviewed after an incident.

There is a shift towards seeing cameras as sensors capable of generating significant volumes of data, Jouna noted.

"It's no longer used as just a camera," he said. "We call it a sensor because it is providing a huge amount of data."

The challenge becomes determining how organisations can turn that data into useful insights.

"There is a lot of data being captured today that is not being used. So how can we make use of this data? That's the big question," he said.

That could see cameras become increasingly integrated with other systems and devices across an organisation.

In a retail environment, as an example, camera analytics can identify customer movements or concentrations and subsequently trigger an action through an audio system.

A camera could identify a particular event, with the resulting data used to trigger an announcement through the connected speaker system.

The concept extends beyond Axis' own products, with potential for a company's security platforms to integrate technologies from third-party providers.

Perimeter security could combine cameras with technologies such as lidar or fibre-optic sensing systems, allowing information from different sensors to be brought together through a common platform.

This shift towards interconnected systems is likely to further blur the traditional distinction between physical security and IT, as organisations seek to use security infrastructure for a broader range of operational purposes.

For IT departments, that creates both an opportunity and a challenge.

Security teams can gain access to increasingly sophisticated analytics and automation capabilities, while businesses can extract additional value from infrastructure that was traditionally deployed primarily to prevent theft, monitor premises or investigate incidents.

At the same time, every connected device introduces another potential entry point into the corporate network, making secure device design, centralised management and ongoing patching increasingly important.

Looking into the future

As for what comes next?

Jouna believes the next major development will be less about cameras, and more about what organisations can do with the data generated at the edge.

As more processing occurs directly on cameras and other edge devices, businesses will be able to analyse information closer to where it is generated before using cloud platforms to manage and connect those systems.

"Having the edge processing becomes very, very important," Jouna said.

The result could be a future where physical security infrastructure is no longer viewed as a standalone system, but as part of an organisation's broader technology environment - generating data, triggering automated actions and feeding insights into business operations.